Bug 2003877
| Summary: | ipa default admin can be deleted from another admin user. | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Varun Mylaraiah <mvarun> |
| Component: | ipa | Assignee: | Thomas Woerner <twoerner> |
| Status: | CLOSED DUPLICATE | QA Contact: | ipa-qe <ipa-qe> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 8.5 | CC: | abokovoy, frenaud, rcritten, tapazogl, tscherf |
| Target Milestone: | rc | Flags: | pm-rhel:
mirror+
|
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-09-14 15:32:44 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Varun Mylaraiah
2021-09-14 04:03:40 UTC
This is not an access control bug. Any admin is an admin in IPA, they aren't different in terms of what they can do if they granted the same level access rights. We do not support environments where 'admin' user or 'admins' group are deleted but we do not prevent such operations because it is not possible to prevent any deletion for all access paths, e.g. cn=Directory Manager account by definition has access with no ACIs applied to itself and can delete any entry in the LDAP database. We have few protected group names but we do not apply this logic to users. Many customers rename 'admin' user to a different name while keeping the account in place. Since that's possible, people can rename it and then remove it, getting around a possible protection. I'd rather close this bug as WONTFIX. I would be in favor of closing as duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=1821181 Delete operation protection for admin user, and continue the discussion on the other bug. Closing this ticket as a duplicated of https://bugzilla.redhat.com/show_bug.cgi?id=1821181. BZ#2003877 was added as a referral link to the parent BZ#1821181. *** This bug has been marked as a duplicate of bug 1821181 *** |